On 12 January 2027 the bill for leaving your cloud provider goes to zero.
Not reduced. Not capped at cost. Zero. Article 29(1) of the EU Data Act: from that date, providers of data processing services shall not impose any switching charges on the customer for the switching process. Article 2(36) folds data egress charges into that definition.
Most contracts in your repository were drafted against different economics. And the machinery that makes a switch executable, the transitional period, the retrieval window, the exit assistance clauses, has been required since the Regulation applied from 12 September 2025 under Article 50.
So the question for your next contract review is not "are we ready for 2027." It is "is the contract we signed last quarter already non-compliant."
An earlier piece covered Data Act scope. This one stays inside Chapter VI: data processing service switching, and the mechanics of exit.
What exactly changes on 12 January 2027, and what has been binding since 12 September 2025?
Two clocks, and teams keep merging them.
Article 29 switching charges phase out in three steps. From 11 January 2024 to 12 January 2027, providers may impose reduced switching charges (Article 29(2)), which shall not exceed the costs incurred by the provider that are directly linked to the switching process concerned (Article 29(3)). From 12 January 2027, none at all (Article 29(1)).
Read the definition first. Article 2(36): charges, other than standard service fees or early termination penalties, imposed for the actions mandated by the Regulation for switching to a different provider or to on-premises ICT infrastructure, including data egress charges. Standard service fees survive. Early termination penalties survive. The egress bill for the exit does not.
The contract clock is separate and it already fired. Article 25(1) requires the customer's rights and the provider's switching obligations to be clearly set out in a written contract, made available prior to signing in a way that lets the customer store and reproduce it.
A third duty is live and routinely missed. Article 29(4): before entering into a contract, providers must give the prospective customer clear information on standard service fees, early termination penalties that might be imposed, and the reduced switching charges applicable during the phase-out window. Article 29(6): where applicable, that information must be publicly available via a dedicated section of the website or another easily accessible way. Testable from outside, today, without asking.
What breaks: teams see "2027" and file Chapter VI on the 2027 roadmap. A contract signed in Q3 2026 without Article 25(2) clauses is not early. It is missing terms already required.
Which clauses must already appear in every data processing service contract you sign?
Article 25(2) is a nine-item checklist. Treat it as a third-party risk control with a pass or fail per line.
(a) Switching clause. Lets the customer, upon request, switch to a different provider or port all exportable data and digital assets to on-premises ICT infrastructure, without undue delay and in any event not after the mandatory maximum transitional period of 30 calendar days, initiated after the notice period in (d). The contract stays applicable throughout.
(b) Exit strategy support. An obligation to support the customer's exit strategy for the contracted services, including by providing all relevant information.
(c) Termination trigger. Contract terminated and the customer notified, on successful completion of switching or at the end of the notice period where the customer wants erasure.
(d) Notice ceiling. A maximum notice period for initiating the switch, not exceeding two months.
(e) Portable data. An exhaustive specification of all categories of data and digital assets that can be ported, including at a minimum all exportable data.
(f) Exempted data. An exhaustive specification of data specific to the internal functioning of the provider's service, exempted where a trade-secret breach risk exists, provided the exemptions do not impede or delay switching under Article 23.
(g) Retrieval window. A minimum data retrieval period of at least 30 calendar days, starting after termination of the agreed transitional period.
(h) Erasure guarantee. Full erasure of exportable data and digital assets generated directly by the customer, or relating to it directly, after the retrieval period or a later agreed date, provided switching completed successfully.
(i) Switching charges that may be imposed under Article 29.
Article 25(3) adds a tenth: clauses letting the customer elect, at the end of the notice period, to switch provider, move to on-premises infrastructure, or erase its exportable data and digital assets.
The two that get skipped are (e) and (f). "Exhaustive specification" is a strong phrase, and a clause saying customer data may be exported in supported formats does not meet it. If the contract does not enumerate what comes out and what is held back, you do not have an exit. You have an intention.
How long can a cloud switch legally take under Article 25?
Do the arithmetic before you give the board a date.
- Notice. The maximum notice period for initiation shall not exceed two months (Article 25(2)(d)). Your contract sets the real figure; two months is the ceiling.
- Transition. The mandatory maximum transitional period then runs 30 calendar days (Article 25(2)(a)), contract still applicable.
- Retrieval. A minimum retrieval period of at least 30 calendar days then starts (Article 25(2)(g)), security maintained across it (Article 25(2)(a)(iv)).
- Erasure. After it expires, or a later agreed date, full erasure follows (Article 25(2)(h)).
Two mechanisms stretch that envelope, asymmetrically. The provider's is Article 25(4): where the mandatory maximum transitional period is technically unfeasible, it shall notify the customer within 14 working days of the making of the switching request, duly justify the unfeasibility, and indicate an alternative transitional period not exceeding seven months, with service continuity ensured throughout.
Yours is Article 25(5): the contract shall give the customer the right to extend the transitional period once, for a period it considers more appropriate for its own purposes.
Diarise day 14: a silent provider past that date is a contractual event, not a project delay.
What breaks: exit plans modelled as "30 days." The floor for a clean exit is notice plus 30 plus 30. The ceiling, if the provider invokes Article 25(4), is notice plus seven months plus a 30-day retrieval window. Plan against the ceiling.
What does the provider actually owe you during the transition, and what counts as 'reasonable assistance'?
On its own, "reasonable assistance" is soft. The four limbs of Article 25(2)(a) make it testable.
Limb (i) is reasonable assistance to the customer and third parties authorised by the customer. Read the second half: your destination provider and your migration integrator fall inside the duty once you authorise them.
Limb (ii) is due care to maintain business continuity and continue providing the contracted functions or services. The service does not get to degrade because you gave notice.
Limb (iii) is clear information on known continuity risks on the source provider's side. Disclosure duties produce artefacts. Ask for the artefact.
Limb (iv) is a high level of security maintained throughout, in particular security of the data during transfer and across the retrieval period.
Article 27 adds an obligation of good faith on all parties involved, including destination providers, to cooperate to make switching effective, enable timely transfer of data and maintain continuity of the service. Most exit plans never pull it.
Article 26 is the information obligation: switching and porting procedures, methods and formats plus known restrictions and technical limitations, and a reference to an up-to-date online register hosted by the provider detailing the data structures, formats, standards and open interoperability specifications in which the exportable data are available. Request the register first. It turns "can we get our data out" into a document you can diff against your schema inventory.
Article 23 sits above it all, obliging providers to remove pre-commercial, commercial, technical, contractual and organisational obstacles to switching. "Contractual and organisational obstacles" is the phrase that matters to a reviewer.
Which services fall outside Chapter VI, and how would you know before you sign?
Article 31 carves out two categories, and both look ordinary on a procurement form.
Custom-built services. Article 31(1) disapplies Article 23 point (d), Article 29, and Article 30(1) and (3) for services of which the majority of main features has been custom-built for the specific needs of an individual customer, or where all components were developed for an individual customer, and which are not offered at broad commercial scale via the provider's service catalogue. Note the boundary: Article 25 is not on that list, so the contract terms survive. The charge withdrawal does not.
Non-production test services. Article 31(2) disapplies the whole Chapter for services provided as a non-production version for testing and evaluation purposes and for a limited period. A sandbox that quietly becomes a production dependency takes your exit rights with it.
Article 31(3) puts the disclosure duty on the provider: before concluding a contract for those services, it shall inform the prospective customer which obligations of the Chapter do not apply.
What breaks: nobody asks, and the carve-out gets asserted at exit rather than at signature. The duty is theirs; the evidence is worthless if it is not in your file.
What technical obligations sit behind the contractual ones?
Article 30 splits providers into two classes.
Infrastructural services (Article 30(1)). Providers of scalable and elastic computing resources limited to infrastructural elements such as servers, networks and virtual resources, which do not give access to the services, software and applications deployed on them, shall take all reasonable measures in their power to facilitate that the customer achieves functional equivalence after switching to a service covering the same service type, by providing capabilities, information, documentation, technical support and the necessary tools.
Functional equivalence is narrower than most exit plans assume. Article 2(37): re-establishing, from the customer's exportable data and digital assets, a minimum level of functionality in the new service of the same service type, where the destination delivers a materially comparable outcome for the same input across shared features supplied under the contract. Not parity.
Everything else (Article 30(2)). Other providers shall make open interfaces available to an equal extent to all customers and concerned destination providers, free of charge, with enough information to enable development of software to communicate with the service for portability and interoperability.
Machine-readable export (Article 30(5)). Where no common specifications or harmonised interoperability standards have been published in the central Union standards repository, the provider shall, at the customer's request, export all exportable data in a structured, commonly used and machine-readable format.
The limits (Article 30(6)). Providers are not required to develop new technologies or services, to disclose or transfer digital assets protected by intellectual property rights or constituting a trade secret, or to compromise security of service. Pair that with Article 25(2)(f) at negotiation: a trade-secret objection raised mid-exit against a category nobody enumerated is a different conversation from one disclosed at signature.
How do you evidence Chapter VI readiness as a control, not a legal opinion?
Chapter VI generates artefacts. That makes it evidenceable, and evidenceable obligations belong in the control framework.
- Inventory your data processing services, not your "cloud vendors." Article 2(8) is the boundary. Record the same service type (Article 2(9)) for each, so you know what a lawful destination is.
- Pull the pre-contract disclosures. Article 29(4) and 29(6): fees, early termination penalties and reduced switching charges, publicly available. Capture with a date. Where nothing is published, the absence is the finding.
- Run the Article 25(2) clause test on every contract. Nine items, plus the Article 25(3) election clause and the Article 25(5) extension right. Score present, partial or absent. Absent is a gap with an owner.
- Request the Article 26(b) register. Diff its structures and formats against the data inventory you hold. Anything in yours missing from theirs is your unportable surface.
- Compute the exit envelope per service. Notice, plus 30 days transition, plus at least 30 days retrieval, with the Article 25(4) seven-month alternative as the stress case.
- Capture the Article 31(3) statement at signature, or record its absence, with the contract.
- Re-test before 12 January 2027. Any switching charge imposed after that date is a contractual defect with a date attached (Article 29(1)).
Steps 2, 4 and 6 produce dated third-party artefacts. That is the difference between "we believe we can exit" and a defensible cloud exit strategy: the evidence is external, dated and attributable to the provider.
Exit planning, continuity, secure transfer and provider oversight are already controls you run for ICT third-party risk. Running the Chapter VI duties through the same control mapping, rather than a parallel Data Act workstream, is cheaper: one control satisfies many obligations, and the overlap resolves once. Answer once. Assess everything. Then audit readiness stops being an exercise in reconstructing what you asked a provider two years ago. The audit pack is a query, not a project.
Map your cloud contracts against EU Data Act Chapter VI obligations and see which clauses are already missing. One organizational profile, deterministic mapping across 245+ regulations in 28 jurisdictions, every obligation traced to a verbatim quote from the source text. Start at agrc.ai
FAQ: EU Data Act cloud switching
When exactly do EU Data Act switching charges go to zero?
From 12 January 2027 (Article 29(1)). From 11 January 2024 to 12 January 2027 providers may impose reduced switching charges (Article 29(2)) not exceeding the costs directly linked to the switching process (Article 29(3)). Under Article 2(36) these include data egress charges, but not standard service fees or early termination penalties.
What is the maximum transitional period for a cloud switch?
30 calendar days, initiated after the maximum notice period, which shall not exceed two months (Article 25(2)(a) and (d)). Where that is technically unfeasible, the provider must notify within 14 working days of the switching request, justify it and indicate an alternative period not exceeding seven months (Article 25(4)). The customer may also extend the transitional period once (Article 25(5)).
Do my existing cloud contracts need to change now, or only by 2027?
Now. The Regulation applies from 12 September 2025 (Article 50), and Article 25(1) requires switching rights and obligations to be set out in a written contract made available before signing in a form the customer can store and reproduce. Only the charge withdrawal carries the 12 January 2027 date.


